Most people skim past the liability clause in a contract. It reads like boilerplate, sits near the back, and rarely gets discussed before signing.
That clause is doing more work than almost anything else in the document. It decides how much you can actually recover if the supplier's service fails, your data is compromised, or a mistake causes real commercial damage. Get it wrong and the rest of the contract barely matters.
What A Liability Cap Actually Does
A liability cap sets the maximum amount a supplier will pay out if something goes wrong, regardless of the actual loss caused. It is not a guarantee of compensation. It is a ceiling on it.
Suppliers set these caps to manage their own risk, not yours. Left unchallenged, the cap in a standard contract is built around what the supplier is comfortable losing, not what the failure could actually cost you.
The Number That Catches Businesses Out
A common default in SaaS and software contracts is a cap set at twelve months' fees, or sometimes as low as one month's fees. On the page, that can look reasonable.
In practice, it rarely reflects the real exposure. Consider what a serious outage, data breach, or service failure could actually cost:
- Lost revenue while the service is down or unusable
- Regulatory fines if the failure involves a data breach
- The cost of remediation, including engineering time to work around the failure
- Damage to a key customer relationship, and the revenue tied to it
- Reputational impact that outlasts the incident itself
A cap set at one month's fees rarely comes close to covering any of this. For a business relying on that supplier for something commercially critical, the gap between the cap and the real cost is where the risk actually sits.
Super Caps: Why They Exist
For higher-risk categories, such as data breaches, confidentiality breaches, or intellectual property claims, well-negotiated contracts often include a "super cap." This is a higher liability limit that applies specifically to those categories, separate from the general cap that covers everything else.
Without a super cap, a data breach caused by the supplier's failure could be capped at the same low figure as a minor service issue. That is rarely an accurate reflection of the relative risk.
What To Check Before You Accept The Cap
- What the general liability cap is, and whether it is tied to fees paid in a fixed period or the full contract value.
- Whether a super cap applies to data breaches, confidentiality, or IP infringement, and if not, why not.
- Whether the cap resets annually or applies once across the life of the contract.
- What is excluded from the cap altogether, since some liabilities, such as death, personal injury, or fraud, are usually uncapped by law.
- Whether the cap reflects the actual commercial value and risk of the relationship, not just the supplier's standard template.
None of this means every cap needs to be uncapped or unlimited. It means the number needs to be a considered commercial decision, not something left unread in a template.
The Bottom Line
A liability cap is not a formality. It is the answer to the question that matters most when something actually goes wrong: how much of the damage will you be left carrying yourself.
If your contracts have liability caps nobody has actually reviewed, book a call with the Ethiqs team.